<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8949063676810574314.post2925550467912038476..comments</id><updated>2011-10-26T17:09:48.745+02:00</updated><category term='facebook'/><category term='full disclousre'/><category term='penetration test'/><category term='exploit'/><category term='security'/><title type='text'>Comments on Quaji: Facebook CSRF attack - Full Disclosure</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.quaji.com/feeds/2925550467912038476/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default?start-index=26&amp;max-results=25'/><author><name>Ronen (ronen at quaji com)</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>37</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-6296461173427958530</id><published>2011-10-26T17:09:48.745+02:00</published><updated>2011-10-26T17:09:48.745+02:00</updated><title type='text'>Sometimes I think ignorance is bliss. What an eye-...</title><content type='html'>Sometimes I think ignorance is bliss. What an eye-opener. Thanks.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6296461173427958530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6296461173427958530'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1319641788745#c6296461173427958530' title=''/><author><name>David</name><uri>http://igtsoft.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1693765837'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-5139798169459817363</id><published>2011-10-19T09:09:43.196+02:00</published><updated>2011-10-19T09:09:43.196+02:00</updated><title type='text'>That is ingenious ... to follow up on Anonymous&amp;#3...</title><content type='html'>That is ingenious ... to follow up on Anonymous&amp;#39; question - has this hole been fixed by now? Seems even browsing with facebook still logged in poses a security risk</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/5139798169459817363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/5139798169459817363'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1319008183196#c5139798169459817363' title=''/><author><name>Mikayla Jones</name><uri>http://www.hackfb.net</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-464320294'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-8427133753343348054</id><published>2011-07-18T11:51:53.036+03:00</published><updated>2011-07-18T11:51:53.036+03:00</updated><title type='text'>Great Post!

What exactly did Facebook do in order...</title><content type='html'>Great Post!&lt;br /&gt;&lt;br /&gt;What exactly did Facebook do in order to resolve this issue?&lt;br /&gt;&lt;br /&gt;Thanks!&lt;br /&gt;Itay.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/8427133753343348054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/8427133753343348054'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1310979113036#c8427133753343348054' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-992467105'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-9133104721089458934</id><published>2010-12-13T22:05:18.770+02:00</published><updated>2010-12-13T22:05:18.770+02:00</updated><title type='text'>Very interesting presentation of the malicious att...</title><content type='html'>Very interesting presentation of the malicious attack techniques. Makes me want to play safe and avoid &lt;a href="http://this1that1whatever.com/blog/2010/11/21-leveraging-social-media-networking.php" rel="nofollow"&gt;social media networking&lt;/a&gt; sites such as &lt;a href="http://this1that1whatever.com/blog/2010/11/02-awesome-facebook-statistical-facts.php" rel="nofollow"&gt;Facebook&lt;/a&gt;, &lt;a href="http://this1that1whatever.com/blog/2010/12/08-twitter-usage.php" rel="nofollow"&gt;Twitter&lt;/a&gt; and &lt;a href="http://this1that1whatever.com/blog/2010/12/02-delicious-experience.php" rel="nofollow"&gt;Delicious&lt;/a&gt;. Are the attacks actually stoppable if those sites worked hard enough at repelling attack attempts?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/9133104721089458934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/9133104721089458934'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1292270718770#c9133104721089458934' title=''/><author><name>David</name><uri>http://this1that1whatever.com/blog/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1504367137'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-4486431617780469400</id><published>2010-06-24T11:37:50.364+03:00</published><updated>2010-06-24T11:37:50.364+03:00</updated><title type='text'>I&amp;#39;ve lately been reading a lot about different...</title><content type='html'>I&amp;#39;ve lately been reading a lot about different vulnerabilities and I keep getting astonished how simple, yet elegant the attacks finally are. This article is no exception to that. Thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4486431617780469400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4486431617780469400'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1277368670364#c4486431617780469400' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1035996055'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-8364542862120565173</id><published>2010-01-30T14:34:25.750+02:00</published><updated>2010-01-30T14:34:25.750+02:00</updated><title type='text'>What was the greatest hidden</title><content type='html'>What was the greatest hidden</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/8364542862120565173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/8364542862120565173'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1264854865750#c8364542862120565173' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-814558072'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-4461952968953654451</id><published>2010-01-13T18:40:45.194+02:00</published><updated>2010-01-13T18:40:45.194+02:00</updated><title type='text'>Good work. Facebook acts as a proxy - and what if ...</title><content type='html'>Good work. Facebook acts as a proxy - and what if you place your own proxy in front of Facebook?&lt;br /&gt;&lt;br /&gt;Watch&lt;br /&gt;&lt;br /&gt;http://www.hacking-lab.com/movies/rp2/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4461952968953654451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4461952968953654451'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1263400845194#c4461952968953654451' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1681345013'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-6185337060898658528</id><published>2009-11-26T23:36:08.776+02:00</published><updated>2009-11-26T23:36:08.776+02:00</updated><title type='text'>I can see how you redirected from firstimage.jpg t...</title><content type='html'>I can see how you redirected from firstimage.jpg to malicious1.php but not how you managed to redirect back to a valid image.&lt;br /&gt;&lt;br /&gt;It seems to me that as soon as I redirect the image to a php and some html is executed, the image breaks. I tried to meta refresh from the php to a valid image, but to no avail.&lt;br /&gt;&lt;br /&gt;Could you elaborate on this?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Jonas&lt;br /&gt;&lt;br /&gt;PS. I&amp;#39;m not talking about this vulnerability but the image-&amp;gt;csrf-&amp;gt;image tactic in general.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6185337060898658528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6185337060898658528'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1259271368776#c6185337060898658528' title=''/><author><name>Jonas</name><uri>http://practicemakesmusic.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1585204100'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-5791511830777871336</id><published>2009-10-05T15:07:20.342+02:00</published><updated>2009-10-05T15:07:20.342+02:00</updated><title type='text'>This will be a pretty useful for all facebook user...</title><content type='html'>This will be a pretty useful for all facebook users. I hope people can get maximum from this. Thanks for the  detailed post.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/5791511830777871336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/5791511830777871336'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1254748040342#c5791511830777871336' title=''/><author><name>wii zubehor</name><uri>http://www.zoombits.de/game-zubehoer/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-179158245'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-2147722983904035793</id><published>2009-09-03T15:47:29.346+03:00</published><updated>2009-09-03T15:47:29.346+03:00</updated><title type='text'>A few clarification:
1. There is no need to pre-ap...</title><content type='html'>A few clarification:&lt;br /&gt;1. There is no need to pre-approve the app. That was in a sense the whole point of the attack. The vulnerable mechanism, aptly called Automatic Authentication, sends the app some information *before* the user approves it.&lt;br /&gt;&lt;br /&gt;2. Only publicly available information was disclosed. So if you set your details to private, you were safe. But as I wrote, the default option is public which means that the vast majority of users have it set just so.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2147722983904035793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2147722983904035793'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251982049346#c2147722983904035793' title=''/><author><name>Ronen (ronen at quaji com)</name><uri>http://www.blogger.com/profile/05471997580954609878</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2109973177'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-7331246726441101870</id><published>2009-08-28T12:04:41.691+03:00</published><updated>2009-08-28T12:04:41.691+03:00</updated><title type='text'>Great article! Thanks :)</title><content type='html'>Great article! Thanks :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/7331246726441101870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/7331246726441101870'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251450281691#c7331246726441101870' title=''/><author><name>NeqO</name><uri>http://www.blogger.com/profile/11076457754991856313</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1918674365'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-139812400681920832</id><published>2009-08-27T07:03:28.824+03:00</published><updated>2009-08-27T07:03:28.824+03:00</updated><title type='text'>Interesting.  This exactly the reason I have compl...</title><content type='html'>Interesting.  This exactly the reason I have completely fake information and photos on my facebook account!   ;-)   bb</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/139812400681920832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/139812400681920832'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251345808824#c139812400681920832' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1948309096'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-6107523713182023336</id><published>2009-08-25T21:24:28.123+03:00</published><updated>2009-08-25T21:24:28.123+03:00</updated><title type='text'>Amazin. Great job :)</title><content type='html'>Amazin. Great job :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6107523713182023336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6107523713182023336'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251224668123#c6107523713182023336' title=''/><author><name>Ivan Pepelnjak</name><uri>http://blog.ioshints.info</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-745526519'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-9140826064044411200</id><published>2009-08-25T17:22:27.768+03:00</published><updated>2009-08-25T17:22:27.768+03:00</updated><title type='text'>Ajuaa con solo colocar el nombre de la persona tam...</title><content type='html'>Ajuaa con solo colocar el nombre de la persona tambien puedes acceder a esa informacion si la persona accede a sus datos aqui le dejo un ejemplo: BUSQUEN EN GOOGLE COOKUI MAUSTER  y ahi les sale el come galleta del video lo unico diferente es que tienes que buscar a la gente si no que atraes a gente seleccionado</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/9140826064044411200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/9140826064044411200'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251210147768#c9140826064044411200' title=''/><author><name>Usuario</name><uri>http://www.blogger.com/profile/11372516926936373811</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_AE73TYLlOBA/SKLjhBbeGiI/AAAAAAAAAAw/MUJiyPY1BB4/s1600-R/Jun-22(8).jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-581301140'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-2254971600625094520</id><published>2009-08-25T12:51:35.121+03:00</published><updated>2009-08-25T12:51:35.121+03:00</updated><title type='text'>Thank you for sharing that information in a detail...</title><content type='html'>Thank you for sharing that information in a detailed post! &lt;br /&gt;&lt;br /&gt;I have a question. You wrote &amp;quot;these details include...&amp;quot; Could you be more precise about the information that is effectively stolen and provide an exhaustive list?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2254971600625094520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2254971600625094520'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251193895121#c2254971600625094520' title=''/><author><name>starbuck</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1156696130'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-6816404477636653982</id><published>2009-08-24T10:53:13.102+03:00</published><updated>2009-08-24T10:53:13.102+03:00</updated><title type='text'>Don&amp;#39;t know what to say other than &amp;quot;it is ...</title><content type='html'>Don&amp;#39;t know what to say other than &amp;quot;it is damn good writing&amp;quot;. &lt;br /&gt;&lt;br /&gt;BTW, this forces me use a dedicated browser for FB. Wonder if it still work under incognito/private window.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6816404477636653982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6816404477636653982'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251100393102#c6816404477636653982' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1962480724'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-4517994200281002225</id><published>2009-08-24T06:11:17.021+03:00</published><updated>2009-08-24T06:11:17.021+03:00</updated><title type='text'>Maybe I&amp;#39;m missing something.  The hacker can g...</title><content type='html'>Maybe I&amp;#39;m missing something.  The hacker can get your user name, profile picture, and friends list.  So what?  He does not have your password.  And he is not a friend to your friends.  So what can he do to you?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4517994200281002225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4517994200281002225'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251083477021#c4517994200281002225' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1169675485'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-5989777731443919646</id><published>2009-08-23T23:53:29.483+03:00</published><updated>2009-08-23T23:53:29.483+03:00</updated><title type='text'>I&amp;#39;m impressed but now I am extremely suspiciou...</title><content type='html'>I&amp;#39;m impressed but now I am extremely suspicious of all apps.  Time to remove some personal info and photos.  We need more info like this.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/5989777731443919646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/5989777731443919646'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1251060809483#c5989777731443919646' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1109013346'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-513725628716270477</id><published>2009-08-21T23:34:07.185+03:00</published><updated>2009-08-21T23:34:07.185+03:00</updated><title type='text'>nice hack!</title><content type='html'>nice hack!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/513725628716270477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/513725628716270477'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250886847185#c513725628716270477' title=''/><author><name>jah</name><uri>http://jahboite.co.uk</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1375019681'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-2720307445526023919</id><published>2009-08-21T23:23:54.655+03:00</published><updated>2009-08-21T23:23:54.655+03:00</updated><title type='text'>Great work!  I&amp;#39;m curious, what specifically ha...</title><content type='html'>Great work!  I&amp;#39;m curious, what specifically has Facebook changed in response to this attack?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2720307445526023919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2720307445526023919'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250886234655#c2720307445526023919' title=''/><author><name>theharmonyguy</name><uri>http://theharmonyguy.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1488969131'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-2331464648914769309</id><published>2009-08-21T22:24:56.827+03:00</published><updated>2009-08-21T22:24:56.827+03:00</updated><title type='text'>I just confirmed that you DO have to have added th...</title><content type='html'>I just confirmed that you DO have to have added the app for this to work. So you have at some point already agreed to give this info to the app. &lt;br /&gt;&lt;br /&gt;That said the writeup is good, just wrong.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2331464648914769309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2331464648914769309'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250882696827#c2331464648914769309' title=''/><author><name>matt</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1755860600'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-2549615846730783569</id><published>2009-08-21T16:54:25.354+03:00</published><updated>2009-08-21T16:54:25.354+03:00</updated><title type='text'>Well played sir.</title><content type='html'>Well played sir.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2549615846730783569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/2549615846730783569'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250862865354#c2549615846730783569' title=''/><author><name>1n4001</name><uri>http://www.null.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-702970964'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-6070048659421198283</id><published>2009-08-21T10:30:19.273+03:00</published><updated>2009-08-21T10:30:19.273+03:00</updated><title type='text'>Hey Ronen Z ,

cool information. By this kind of a...</title><content type='html'>Hey Ronen Z ,&lt;br /&gt;&lt;br /&gt;cool information. By this kind of attacks have been already been notified Its more like Phishing :-) , But still yes you have done a great Job in explaining it i appreciate it ;-)&lt;br /&gt;&lt;br /&gt;Regards&lt;br /&gt;Vijay</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6070048659421198283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/6070048659421198283'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250839819273#c6070048659421198283' title=''/><author><name>Vijay</name><uri>http://vijayvkvelu.blogspot.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1153458836'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-4408568818588382668</id><published>2009-08-21T00:26:45.534+03:00</published><updated>2009-08-21T00:26:45.534+03:00</updated><title type='text'>IT dosnt say it.  Have you tried it? The video is ...</title><content type='html'>IT dosnt say it.  Have you tried it? The video is by the developer of the app. (who automaticaly is added to the app).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4408568818588382668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4408568818588382668'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250803605534#c4408568818588382668' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1755860600'/></entry><entry><id>tag:blogger.com,1999:blog-8949063676810574314.post-4484920675771803600</id><published>2009-08-20T23:15:54.518+03:00</published><updated>2009-08-20T23:15:54.518+03:00</updated><title type='text'>To &amp;#39;anonymous&amp;#39;: Where does it say you have...</title><content type='html'>To &amp;#39;anonymous&amp;#39;: Where does it say you have to have added the app?  The description and video would appear to indicate that you do *not* have to do this at all.&lt;br /&gt;&lt;br /&gt;To inquirer: An HTTP server can respond to any request with a redirect, that&amp;#39;s independent of what&amp;#39;s being requested.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4484920675771803600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8949063676810574314/2925550467912038476/comments/default/4484920675771803600'/><link rel='alternate' type='text/html' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html?showComment=1250799354518#c4484920675771803600' title=''/><author><name>Anton</name><uri>http://www.visi.com/~rang/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html' ref='tag:blogger.com,1999:blog-8949063676810574314.post-2925550467912038476' source='http://www.blogger.com/feeds/8949063676810574314/posts/default/2925550467912038476' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1951412342'/></entry></feed>
